mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-10-05 08:22:13 +00:00
24 lines
1.1 KiB
JSON
24 lines
1.1 KiB
JSON
|
|
{
|
||
|
|
"_comment": "Offline advisory fixture for dependency-cve.sh --canary (and --advisories-file). This stands in for the live OSV querybatch API so the canary is fully offline + deterministic. Each entry is keyed by 'ECOSYSTEM|package|version' (ECOSYSTEM matches OSV ecosystem names: PyPI, npm, NuGet) and carries the fields the checker emits in a finding's proof. These mirror REAL advisories (GHSA/CVE ids + summaries + fixed versions) so the fixture is realistic, but the checker NEVER reaches the network in canary mode — it reads only this file.",
|
||
|
|
"advisories": {
|
||
|
|
"PyPI|jinja2|2.11.2": [
|
||
|
|
{
|
||
|
|
"id": "GHSA-g3rq-g295-4j3m",
|
||
|
|
"summary": "Jinja2 ReDoS in the urlize filter via the urlize regex",
|
||
|
|
"severity": "high",
|
||
|
|
"cvss": 7.5,
|
||
|
|
"fixed_version": "2.11.3"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"npm|lodash|4.17.15": [
|
||
|
|
{
|
||
|
|
"id": "GHSA-p6mc-m468-83gw",
|
||
|
|
"summary": "Prototype pollution in lodash (zipObjectDeep / set / setWith)",
|
||
|
|
"severity": "high",
|
||
|
|
"cvss": 7.4,
|
||
|
|
"fixed_version": "4.17.19"
|
||
|
|
}
|
||
|
|
]
|
||
|
|
}
|
||
|
|
}
|